1. Scope and our role
Blogged is a product owned and operated by BoostYard LLC, a Delaware limited liability company. In this policy, “Blogged,” “we,” “us,” and “our” mean BoostYard LLC.
This Privacy Policy applies to Blogged's marketing website, documentation, account and workspace experience, support communications, billing relationship, and the services used to research, create, optimize, schedule, host, and measure customer content. It does not replace the privacy notice of a Blogged customer whose published blog you visit.
Blogged is a controller or business for account, billing, support, security, and marketing-site information that it determines how to use. When Blogged hosts a customer's blog or processes its subscribers, leads, content, private knowledge, analytics, or publication instructions, the customer is normally the controller or business and Blogged acts as its processor or service provider. The Data Processing Addendum governs that processing.
For workspace invitations, the customer selects the recipient and role and instructs Blogged to deliver the invitation. Blogged separately determines the processing needed to secure the invitation, maintain account and membership records, prevent abuse, and decide whether an account may receive a one-time signup benefit.
Customer blogs
The customer decides what to publish, what forms and calls to action to use, whether to add analytics or advertising tags, and what privacy notice applies to its readers. Direct privacy requests about a customer's blog should normally go to that customer first.
2. Information we collect
| Category | Examples | Sources |
|---|---|---|
| Account and workspace | Name, work email, authentication identifiers, profile details, SaaS URL, workspace membership and role, plus invitation recipient email, inviter, assigned role, delivery state, expiration, acceptance or revocation state, and related audit and anti-abuse records | You, workspace owners or admins who invite you, Firebase Authentication, Google Sign-In when selected, and Resend delivery events |
| Customer content and instructions | Product descriptions, strategy, topics, briefs, drafts, posts, revisions, sources, uploaded documents, knowledge facts, competitors, images, brand settings, publication schedules, prompts, and feedback | You, authorized workspace members, customer-approved public sources, and product workflows |
| Free-tool submissions | Submitted public website URL; extracted titles, headings, page text, canonical and indexability signals, internal-link relationships, crawl coverage, generated recommendations and coding-agent prompt; signed browser, account, hashed network, quota and abuse-control records | You, the public website you confirm you are authorized to analyze, your browser and network, Blogged systems, and Google Cloud Vertex AI |
| Publishing and integration data | Domains, DNS verification state, blog settings, Search Console property data, OAuth scopes and encrypted tokens, tracker IDs, custom code, webhook settings, and delivery results | You, your connected services, your website, and service providers |
| Billing and commercial | Signup-benefit assignment, Free-grant and trial usage, plan, subscription status, invoices, billing address, tax status, promotion codes, payment outcome, and Stripe customer or subscription identifiers | You, your workspace, and Stripe. Blogged does not receive full payment-card numbers |
| Free Project offer verification | Submitted X post URL and post ID; public post text and links read during verification; author handle and publication time; required Blogged handle and blog-address matches; associated account, workspace, Project and Free-grant identifiers; and verification or consumption time | You, the public X or Twitter post you submit, X's public embed infrastructure, and Blogged systems |
| Support and communications | Messages, requests, survey or feedback responses, billing-notice delivery, bounce and complaint status, and related account context | You, your team, and communications providers |
| Public roadmap and product feedback | Feature-request title, description and category; comment text; name, email, optional consent to publish the name, moderation state, anonymous vote state, and purpose-limited hashed browser or network anti-abuse records | You, your browser and network, Blogged systems, and Blogged operators. Email addresses are not published |
| Device, usage, and security | IP address, browser and device data, timestamps, page or feature interactions, logs, error details, authentication events, rate-limit records, and anti-abuse signals | Your browser, device, network, and Blogged systems. Some rate-limit records store a one-way hash of the IP address |
| Customer-blog reader data | Lead email, lead-form data, consent or preference state, on-site searches, reader feedback, CTA views and clicks, campaign parameters, and page-level engagement events | Readers of customer blogs, under the customer's configuration and instructions |
Please do not submit government identifiers, payment-card data, health information, biometric data, precise location, or other sensitive personal information to prompts, briefs, knowledge, uploads, custom code, or support unless Blogged has expressly agreed in writing that the use is supported.
3. How we use information
- Provide and operate accounts, workspaces, projects, the Editor, Knowledge, Assets, Competitor Blog Watch, Blog Site, Insights, and Autopilot.
- Operate bounded free tools, crawl an authorized submitted public website, build its internal-link graph, generate a private implementation plan, enforce daily and monthly limits, and prevent automated abuse.
- Scan customer-directed public sources, perform web research, generate and review content and images, maintain knowledge provenance, and run publication safeguards.
- Host blogs, serve previews, connect domains, publish or unpublish posts, process forms, deliver customer-configured webhooks, and measure content performance.
- Authenticate users, maintain permissions, secure credentials, prevent fraud and abuse, rate-limit public endpoints, debug failures, and preserve service reliability.
- Create, deliver, verify, expire, renew, revoke, and audit workspace invitations; match an invitation to its intended account; and prevent invitation spam or abuse.
- Administer Free grants, trials, subscriptions, taxes, invoices, plan allowances, lifecycle reminders, cancellations, payment recovery, and transactional billing notices.
- Verify a submitted public X post, prevent a post or signup benefit from being reused, and activate an eligible one-time Free Project.
- Answer support requests, communicate service and policy changes, send Free-Project onboarding or upgrade messages where permitted, and improve product usability and performance.
- Meet legal obligations, enforce agreements, resolve disputes, and protect Blogged, customers, readers, and the public.
Where the GDPR or UK GDPR applies, the usual legal bases are performance of a contract, legitimate interests in operating and securing a business service, compliance with law, and consent where consent is required, including for certain cookies or connected services. You may withdraw consent without affecting processing that occurred before withdrawal.
Promotional Free-Project messages include one-click unsubscribe and an account-level marketing preference. Unsubscribing from marketing does not disable neutral operational notices about a dated archive, unpublish, security, billing, or material service change. Blogged still suppresses delivery to an address after a hard bounce or spam complaint.
4. AI, research, and autonomous publishing
Blogged sends the instructions and context needed for a task to Google Cloud's Vertex AI services. That context may include customer prompts, briefs, product facts, excerpts from approved sources, draft content, feedback, and image instructions. In production, Blogged uses Vertex AI under Google Cloud terms. Google states that it does not train or fine-tune its AI models on customer data without permission or instruction, although limited logging may occur for security and abuse monitoring under its terms.
For the SaaS Internal Link Tool, Blogged sends a bounded plain-text page inventory, headings, excerpts, graph metrics, and server-generated candidate identifiers to Vertex AI. Raw HTML is not retained or sent as the analysis record, and the model may select only candidate page pairs that Blogged generated and validates. Signed-out results stop being accessible after 24 hours; signed-in results stop being accessible after 30 days.
Blogged uses Exa to search the public web for research and competitor context. Search queries should not contain personal or confidential information. Results and source excerpts may be stored with the relevant research, knowledge, or draft record so a customer can review provenance and publication decisions.
Full Autopilot can schedule and publish content when the customer has enabled it and the configured direction, eligibility, and governance checks pass. Assisted mode waits for human review. Blogged records workflow state, approvals, holds, revisions, and publication evidence to operate these controls and investigate failures.
When a customer submits an X post to claim a Free Project, Blogged reads the public post text and links only to test the displayed eligibility conditions. A successful verification record stores the post ID, author handle, posting time, associated Blogged account, workspace, Project and grant identifiers, and consumption time. It does not store the successful post's full text or links in that verification record.
5. Google account and Search Console data
If you connect Google Search Console, Blogged requests the scopes displayed during Google's authorization flow. Blogged uses that access to list and verify properties, read search performance and URL inspection information, synchronize reports, and, only when the granted scope allows and you request it, submit a sitemap. OAuth tokens are encrypted at rest. Disconnecting the integration revokes the token with Google and removes the active connection from Blogged.
Limited use
Blogged's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold, or used to train generalized AI models.
7. Customer-controlled trackers, forms, and webhooks
A customer may add Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, or custom head code to its published blog. The customer decides whether to use those tools and is responsible for a lawful basis, notice, consent, vendor terms, and honoring reader choices. Custom code executes in the blog page and may collect or disclose information independently of Blogged.
When enabled by the customer, Blogged's blog cookie banner describes the configured tag categories and stores the reader's accept or decline choice in local storage for 180 days. Do Not Track and Global Privacy Control disable customer-configured tags by default unless the customer deliberately overrides that setting. Blogged's first-party, aggregated reporting continues to honor those signals.
Customer-configured lead webhooks can send subscriber or lead details to the customer's endpoint. After delivery, the recipient's privacy practices govern its copy. Blogged applies destination validation and delivery controls, but the customer remains responsible for the endpoint, recipient, and requested fields.
8. Retention and deletion
Blogged keeps personal information for as long as needed to provide the service, maintain an active business relationship, comply with law, resolve disputes, protect security, and enforce agreements. Retention depends on the record and its purpose rather than one blanket period.
- Account, workspace, project, content, knowledge, asset, publication, and integration records generally remain while the account or relevant project is active. Archiving a project pauses active work but is not deletion. For an unpaid Free Project that has fully used its post or image capacity, Blogged schedules archive 14 days after the first capacity is fully used and stops serving its hosted blog 30 days after that event unless the Project upgrades first.
- Short-lived previews expire after their configured lifetime. Operational jobs, leases, idempotency records, and some execution traces expire under service-specific schedules when they no longer support recovery or audit needs.
- Signed-out SaaS Internal Link Tool runs, extracted page records, and results become inaccessible after 24 hours. Signed-in runs and results become inaccessible after 30 days. Firestore TTL removes expired records asynchronously. Purpose-limited hashed quota and abuse records may remain through the applicable calendar-month enforcement and security window; raw IP addresses are not stored in those ledgers.
- Workspace invitation links expire after 7 days. An invitation record is scheduled for deletion 180 days after it expires, is accepted, or is revoked. A terminal invitation-email outbox record is scheduled for deletion after 30 days, an invitation operation record after 7 days, and a daily invitation rate-limit record after 2 days. Related account, membership, audit, suppression, security, and backup records follow their own purposes and retention periods.
- Public-roadmap rate-limit records are scheduled for deletion after 24 hours. Rejected or spam roadmap submissions and comments are scheduled for deletion after 90 days. Feature-request contact records and private comment contact records are scheduled for deletion after 24 months unless an earlier verified deletion request applies. Approved public comment text and product roadmap history may remain while they serve the public feedback record; the associated email is not part of that public record.
- A successful Free Project share-verification record and an invitation-based signup-benefit exclusion may be kept as durable anti-abuse and eligibility records while reasonably needed to prevent repeated introductory benefits, enforce the offer, and resolve disputes. Blogged limits those records to the identifiers and timestamps needed for those purposes.
- Billing, tax, invoice, contract, fraud-prevention, payment-recovery, and suppression records may be kept for legal, accounting, security, or deliverability obligations after service ends.
- Unsubscribed customer-blog readers remain marked unsubscribed so the customer does not contact them again. Authorized customer users can permanently delete lead records in the product.
- Deletion from active systems may not immediately remove encrypted backups, disaster-recovery copies, or records that law requires Blogged to retain. Those copies remain protected and age out under normal cycles.
Because the current product supports project archive and restore rather than full self-service account erasure, contact Blogged to request deletion of an account or workspace. Blogged will verify authority and explain any data that must be retained or that belongs to another workspace member or customer.
9. Security
Blogged uses technical and organizational safeguards designed for the nature of the service, including role-based workspace access, server-enforced tenant boundaries, encryption in transit, managed cloud encryption at rest, encrypted Search Console tokens, restricted secret storage, audit and revision records, rate limits, webhook destination validation, and monitoring. No internet service can guarantee absolute security.
You are responsible for protecting account credentials, assigning the minimum necessary workspace role, reviewing who can publish or configure executable code, and notifying Blogged promptly of suspected unauthorized access.
10. International transfers
Blogged and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws from your location. Where required, Blogged uses contractual protections such as the European Commission's Standard Contractual Clauses, the UK transfer addendum, provider data-processing terms, or another lawful transfer mechanism. More detail appears in the Data Processing Addendum and Subprocessor List.
11. Your privacy rights
Depending on your location and Blogged's role, you may have rights to access, know, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, opt out of certain disclosures, and appeal a decision. You may also complain to your local data-protection authority. Blogged will not discriminate against you for exercising a privacy right.
Send a request to hi@blogged.dev. Describe the account, workspace, blog, or email address involved and the right you want to exercise. Blogged may verify identity and authority before acting. If Blogged processes the information only for a customer, it may direct the request to that customer or help the customer respond.
12. California privacy notice
The table in Section 2 describes the categories of personal information collected during the preceding 12 months, the sources, and representative data elements. Sections 3 and 6 describe business purposes and recipient categories. Blogged may collect identifiers, customer records, commercial information, internet or electronic activity, professional information, approximate location derived from IP address, audio or visual content a user uploads, and inferences used to provide product strategy or security. Blogged does not intentionally collect sensitive personal information for inferring characteristics.
Blogged has not sold personal information for money. It has disclosed identifiers, commercial information, internet activity, and customer-directed content to service providers for the business purposes described here. To exercise rights to know, access, correct, delete, or obtain portability, use the contact method in Section 11. Measurement on Blogged's own surfaces remains off until the visitor explicitly allows it. A Global Privacy Control signal suppresses Meta and Reddit advertising measurement and is treated as an opt-out signal on supported customer-blog tracking surfaces. Blogged does not knowingly sell or share personal information of anyone under 16.
13. Children
Blogged accounts and autonomous content services are for business users who are at least 18 or the age of legal majority where they live. Blogged does not knowingly create accounts for children. Customer blogs are public websites controlled by customers; customers are responsible for ensuring their content, forms, trackers, and audience practices are appropriate for their intended readers.
14. Changes and contact
Blogged may update this policy as the service, providers, or law changes. The effective date at the top identifies the current version. Material changes will receive additional notice when required by law or when they materially change how existing account or Google user data is used.
For privacy questions or requests, contact BoostYard LLC at hi@blogged.dev or write to: BoostYard LLC, Attn: Privacy, 16192 Coastal Highway, Lewes, DE 19958, United States.
Questions about this policy?
Include the relevant workspace, customer blog, public URL, or account email so the request can be routed without collecting unnecessary information.
Email hi@blogged.devRelated policies